CVE-2025-31510
HIGHLemonLDAP::NG < 2.16.5 and 2.17.0-2.21.0 - Cross-Site Scripting via Tab Parameter
Title source: llmDescription
In the portal in LemonLDAP::NG before 2.21.0, cross-site scripting (XSS) allows remote attackers to inject arbitrary web script or HTML (into the login page) via the tab parameter, for Choice authentication.
References (2)
Core 2
Core References
Scores
CVSS v3
7.2
EPSS
0.0038
EPSS Percentile
29.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-79
Status
published
Products (2)
lemonldap-ng/LemonLDAP::NG
2.0.8 - 2.16.5
lemonldap-ng/LemonLDAP::NG
2.17.0 - 2.21.0
Published
Jan 16, 2026
Tracked Since
Feb 18, 2026